Privacy Policy

Last updated August 14, 2026

This describes what happens to information you put into the service. It is written from the code, not from a template — where we say we do not do something, it is because there is nothing in the software that does it.

What we do not collect

Starting here, because it is shorter and it is the part most policies bury:

  • No analytics. No Google Analytics, no Plausible, no PostHog, no session recording, no heatmaps. There is no analytics or product-telemetry service in this application at all.
  • No tracking pixels and no advertising. We do not run ads and we are not in an ad network.
  • No third-party cookies. The only cookies we set are the ones that keep you signed in.
  • We do not sell your data, and we do not share it for anyone else's marketing.
  • We do not use your uploaded work to train machine-learning models, and we do not give it to anyone who does.

What we collect

Your account. Email address, password (stored hashed, never in readable form), display name, and — if you set them — your public handle, avatar, background image, bio and the contact links you choose to show. If you sign in with Google or GitHub instead, we receive your email address and basic profile from them.

Your work. Projects and their titles, client names, deadlines, private notes, payment amounts you record, commission sheets, and the images you upload. Images are stored in private object storage and are only served through an access check.

Requests from your clients. When someone fills in the request form on one of your published commission sheets, we store what they entered — their name, email address, what they are asking for — and email it to you. That person does not have an account here. See "About your clients' data" below.

Subscription records. If you subscribe to a paid plan we store which plan you are on, when the period ends, and the identifiers our payment provider gives us to recognise your subscription. We never see or store your card details — those go to the payment provider directly and never reach our servers.

Waiting list. If you asked to be told when paid plans opened, we stored your email address and which plan you were interested in. Nothing else.

Technical records. Server logs kept by our hosting provider, and a rate-limiting table that records a counter against your account or against an IP address. The IP address is there to stop one person flooding the request form; it is not used to build a profile and it is not linked to your browsing.

Cookies

Only session cookies, set by the authentication system so that you stay signed in and so that sign-in forms cannot be submitted from another site. There is no consent banner because there is nothing to consent to beyond what the service needs to function.

Who else touches it

We use a small number of providers. Each one only receives what it needs to do its job:

ProviderWhat it doesWhat it sees
VercelHostingRequests to the site, server logs
NeonDatabaseEverything stored in the database
Cloudflare R2Image storageYour uploaded images
ResendSending emailRecipient address and message content
Google / GitHubOptional sign-inOnly if you choose to sign in that way
CreemSubscription payments, as merchant of recordYour email address, billing details and card data, which it handles and we never receive

About your clients' data

Some of what is stored here is about people who never signed up: the client name on a project, the person who filled in a request form.

You decide what to record about them and what to publish. We hold it and act on your instructions. Where data protection law applies to it, you are the controller of that information and we are your processor. If one of your clients asks you to remove their details, you can do it yourself by editing or deleting the project or the request — and if you need help, ask us.

Anyone who submitted a request to an artist here and wants it deleted can also contact us directly, using the address at the bottom of this page.

What is public, and what never is

Public project pages show the title, client name, dates, stage and images of that project. They never show payment amounts, your private notes, or your account email — those are excluded when the page is built, not merely hidden with styling.

Public pages are not offered to search engines: they carry noindex, are excluded from our sitemap and are disallowed in robots.txt. Social platforms can still generate link previews for a link someone shares — except for projects marked Mature (18+), where no preview image is produced.

How long we keep it

While your account exists, we keep what you put in it — that is what the service is for.

Deleting your account deletes your projects, your uploaded images from storage, your payment records and your commission sheets, and any published share link stops working immediately. It is not reversible; we cannot restore it afterwards.

Backups and provider logs expire on their own schedules, generally within a few weeks. Records of payments, which tax and accounting law requires us to retain, are kept for as long as the law requires and used for nothing else — this is the one category that survives deleting your account.

Your rights

You can ask us to give you a copy of your data, correct it, or delete it. Most of it you can do yourself from the app; for anything you cannot, write to the address below and we will do it.

These are offered to everyone, not only where a law requires them. If the law where you live grants you more — portability, objection, a complaint to a regulator — those apply too, and we will not make you argue for them.

Security

Images live in a private bucket with no public URL, served only after an access check on each request. Passwords are hashed. Traffic is encrypted in transit.

No service is perfectly secure. If we discover a breach affecting your data, we will tell you what happened, what was affected, and what to do about it — promptly, and without waiting to have a good explanation.

Children

The service is not for anyone under 13, and we do not knowingly collect their information. Between 13 and 17 it may be used with a parent or guardian's consent and supervision — see the Terms of Service. If you believe a child under 13 has given us data, tell us and we will remove it.

Publishing adult work requires being 18 or over. Access to a page marked Mature (18+) is gated by a click-through confirmation rather than by identity checks; where a law requires stronger verification, we will implement what it requires.

Where your data is

The service is operated from China and our providers operate internationally, so your data is processed outside your own country. Where the law requires a mechanism for that transfer, we rely on the standard data-transfer terms our providers publish.

Changes

Changes are posted here with a new date at the top. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect.

Who to contact

This service is operated by Li Pengpeng.

support@artcommissiondesk.com